Vulnerabilities > Fourtwosevenbb

DATE CVE VULNERABILITY TITLE RISK
2008-06-06 CVE-2008-2561 Cross-Site Scripting vulnerability in Fourtwosevenbb 427Bb 2.3.1
Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to (a) register.php, (b) reminder.php, and (c) search.php; the (2) uname, (3) email, and (4) email2 parameters to register.php; the (5) email parameter to reminder.php; and the (6) keywords parameter to search.php.
4.3
2008-06-06 CVE-2008-2560 SQL Injection vulnerability in Fourtwosevenbb 427Bb 2.3.1
SQL injection vulnerability in showpost.php in 427BB 2.3.1 allows remote attackers to execute arbitrary SQL commands via the post parameter.
network
low complexity
fourtwosevenbb CWE-89
7.5